Impact
The flaw arises from improper control of code generation in the schedule feature of Devolutions PowerShell Universal. An authenticated user who has permission to create a schedule can supply crafted parameter names that are concatenated into a PowerShell script invocation. This allows the user to inject arbitrary PowerShell commands that will execute in the context of the scheduling process, providing the ability to run any code the user wishes.
Affected Systems
Devolutions PowerShell Universal versions 2026.2.2 and earlier are affected. The vulnerability exists specifically in the scheduling component of the product for any installation of these earlier releases.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact with the potential for full system compromise. The EPSS score of less than 1% implies that the probability of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. However, because the vulnerability requires authentication and schedule‑creation privileges, the attack vector is likely an internal privileged user who can create a malicious schedule. If an attacker gains such credentials, they could execute arbitrary PowerShell code with the permissions of the scheduling engine, potentially compromising the host and any network resources visible to that process.
OpenCVE Enrichment